Cybersecurity

Two Nikkei Email Accounts Hacked, One Used to Send 9,000 Phishing Messages

Nikkei revealed that a Google Workspace account was hacked in July and a Microsoft 365 account in September, potentially exposing the data of 1,646 people and resulting in the second account being used to send 9,000 phishing messages.

2026-10-06
3 min read
18 views
certi.news Editorial Team
Two Nikkei Email Accounts Hacked, One Used to Send 9,000 Phishing Messages

Japanese publisher Nikkei announced that unidentified attackers managed to access two employee email accounts in two separate incidents involving Google Workspace and Microsoft 365. The second account was used to send thousands of fraudulent messages to employees and people who had previously communicated with the company.

What happened?

In late July, the attackers gained access to an employee’s Google Workspace account. Nikkei said the incident may have exposed the names and email addresses of 1,646 employees and business partners, but confirmed that the affected data did not include information about readers or people it had interviewed.

The company received a notification from Google about the incident and discovered the breach in early August, then changed the account’s password. Nikkei did not specify how long the attackers had access to the account or whether the data was actually copied.

Microsoft 365 Account Turned into a Phishing Tool

In a more recent incident, attackers accessed another employee’s Microsoft 365 account during September. On September 30, the account was used to send emails to Nikkei employees and to people who had previously communicated with several of its staff members.

The messages contained links to malicious websites, and their number reached approximately 9,000. The company changed the passwords associated with the incident and said it had not detected any unauthorized logins since then. It also contacted the recipients individually and asked them to delete the messages.

Why does this matter?

The danger of corporate email account breaches is not limited to exposing data; a compromised account can be used to send seemingly trustworthy messages to colleagues, partners, and people who have a prior relationship with the employee. This increases the chances of phishing succeeding, particularly when the message comes from a known domain and relies on real contacts.

Nikkei warned affected people about new messages that may impersonate it or the names of its subsidiaries. The company did not attribute either attack to a specific entity or hacking group, nor did it confirm a connection between the two incidents.

A Recurring Security Context

The new disclosures come after other incidents announced by Nikkei in previous years. The previous year, its Slack platform was breached, affecting more than 17,000 employees and business partners. In May 2022, Nikkei’s Singapore company was hit by a ransomware attack targeting a server that was believed to contain customer data. Nikkei America also lost approximately $29 million in a business email compromise (BEC) fraud attack in September 2019.

Important questions remain open, including the nature of the data that may actually have been accessed, the precise duration of each breach, and whether the two incidents were connected. Therefore, the information published so far remains sufficient to confirm the two breaches and their initial effects, but it does not establish a complete criminal or technical scope of the attack.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

What you need to know

أعلنت Nikkei عن اختراق حساب موظف على Google Workspace في أواخر يوليو وحساب آخر على Microsoft 365 خلال سبتمبر. ربما تعرضت أسماء وعناوين بريد إلكتروني لـ1,646 موظفاً وشريكاً تجارياً للخطر، بينما استُخدم حساب Microsoft 365 المخترق لإرسال نحو 9,000 رسالة تصيد.

  • تمكن مهاجمون مجهولون من الوصول إلى حساب موظف على Google Workspace، وربما اطلعوا على أسماء وعناوين بريد إلكتروني تخص 1,646 شخصاً.
  • لم تحدد Nikkei مدة الوصول إلى حساب Google Workspace أو ما إذا كانت البيانات قد نُسخت فعلياً.
  • استُخدم حساب موظف آخر على Microsoft 365 في 30 سبتمبر لإرسال نحو 9,000 رسالة تحتوي على روابط لمواقع ضارة.
  • وصلت رسائل التصيد إلى موظفي Nikkei وأشخاص سبق لهم التواصل مع العاملين في الشركة، ما جعل الرسائل تبدو أكثر موثوقية.
  • غيّرت Nikkei كلمات المرور المرتبطة بالحادثين، وقالت إنها لم ترصد عمليات تسجيل دخول غير مصرح بها منذ ذلك الحين.
  • لم تنسب الشركة الهجومين إلى جهة محددة ولم تؤكد وجود صلة بينهما، ولا تزال طبيعة البيانات التي جرى الوصول إليها والمدة الدقيقة للاختراق غير واضحة.

FAQ

ما الخدمتان اللتان تعرضتا للاختراق؟

شمل الحادثان حساباً على Google Workspace وحساباً آخر على Microsoft 365.

كم رسالة تصيد أُرسلت من الحساب المخترق؟

أُرسلت نحو 9,000 رسالة تصيد تحتوي على روابط إلى مواقع ضارة.

ما البيانات التي ربما تعرضت للخطر؟

ربما تعرضت أسماء وعناوين البريد الإلكتروني لـ1,646 موظفاً وشريكاً تجارياً للخطر، بينما قالت Nikkei إن بيانات القراء والأشخاص الذين أجرت معهم مقابلات لم تكن ضمن البيانات المتأثرة.

هل ثبت أن الهجومين مرتبطان؟

لا، لم تؤكد Nikkei وجود صلة بين الحادثتين ولم تنسبهما إلى جهة أو مجموعة قرصنة محددة.

Explore this story

الموضوعات والجهات المرتبطة

In the same category

You may also like

View all news